vendor:
D301 & D151
by:
BenChaliah
7.5
CVSS
HIGH
Unauthenticated Configuration Download
287
CWE
Product Name: D301 & D151
Affected Version From: D301 1.2.11.2_EN
Affected Version To: D151 V2.0 50.21.1.5_EN
Patch Exists: NO
Related CWE: N/A
CPE: h:tenda:d301
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2021
Tenda D151 & D301 – Configuration Download (Unauthenticated)
This exploits allows for the download of the current router config including the admin login, just by requesting {IP}/goform/getimage, you can also activate telnet service by requesting /goform/telnet. Telnet activation issue exists in many other tenda devices too.
Mitigation:
Ensure that authentication is required for any configuration download requests.